IoT
security.
Whole-ecosystem testing of connected products — device, wireless, cloud, and companion app — against ETSI EN 303 645, NIST IR 8259, and the regulations shipping next.
One product. Four surfaces. One attacker.
A connected product is never one thing. Attackers chain a BLE flaw into a cloud weakness into a fleet-wide compromise — in an afternoon. We test the ecosystem the way they do: coordinated, across every surface, with operators who speak radio, firmware, backend, and mobile equally.
Engagements produce evidence suitable for ETSI EN 303 645, NIST IR 8259, UK PSTI, and EU CRA conformance — with remediation prioritized by fleet-level impact.
Every surface. One assessment.
Physical teardown, debug-interface exploitation, firmware extraction, and secure-boot / OTA analysis on the device itself.
Wi-Fi, BLE, Zigbee, Z-Wave, Thread, Matter, LoRaWAN, and proprietary RF — capture, replay, and protocol-level attacks.
MQTT / CoAP / AMQP brokers, device-provisioning APIs, multi-tenant isolation, and the authenticated REST / GraphQL behind the app.
iOS and Android mobile apps against OWASP MASVS — including binding, pairing, and device-recovery abuse.
Device identity lifecycle, certificate handling, onboarding attacks, and manufacturer-trust abuse.
OTA signing, delivery integrity, rollback protection, and upstream supply-chain dependency risk (SBOM, SLSA).
Model. Cross-test. Scale. Verify.
Ecosystem Threat Model
Whole-product threat model — device, wireless, cloud, app, and identity — aligned to ETSI EN 303 645, NIST IR 8259, and the EU CRA.
Cross-Surface Testing
Coordinated testing across every surface by operators who chain findings into real-world compromise — not isolated silo assessments.
Abuse & Scale Analysis
Fleet-level reasoning — what happens when an attacker pivots from one device to the cloud, or from the cloud to every device.
Reporting & Retest
Standard-aligned findings, regulator-ready evidence, and a verified retest after remediation.
What ships.
- 01Whole-ecosystem threat model (device, wireless, cloud, app)
- 02Cross-surface exploit chains and abuse scenarios
- 03ETSI EN 303 645 / NIST IR 8259 coverage matrix
- 04Regulator-ready evidence for UK PSTI and EU CRA readiness
- 05Remediation roadmap prioritized by fleet-level risk
- 06Verified retest after remediation
Secure the
whole ecosystem.
Pre-launch assessment, postmarket continuous testing, or regulatory-readiness engagement. Scoped under NDA.